supply-chain-guard
js
Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs
Version 5.2.32 License Apache-2.0
Keywords
securitysupply-chainmalware-detectionnpmpypicargogolangdockerterraformglasswormshai-huludscannercligithub-actionsarif
INSTALL